Range-diff !486

back to !486 keys: optional expiry for SSH and deploy keys

 -:  ------- >  1:  9f77ab1 store: announce key revocations; LiveSSHKeys
 -:  ------- >  2:  bf64c30 gitutil: Transport takes a cancel channel and kills its process group
 -:  ------- >  3:  c096948 sshd: re-read the key per exec; revocation cuts its connections
 -:  ------- >  4:  2b84081 e2e: removing a key cuts its multiplexed connection and a push in flight
 -:  ------- >  5:  4bbf4f8 wiki: revocation closes open connections
 -:  ------- >  6:  4b94fa9 store: tokens and keys record the token that created them; chained revoke
 -:  ------- >  7:  89dd0a3 control: expiring credentials cannot run credential-minting commands
 -:  ------- >  8:  dd36248 token: default --scope read; record the creating token; revoke --created
 -:  ------- >  9:  ed682bb e2e: expiring tokens refused on minting; revoke --created
 -:  ------- > 10:  0787c7c wiki: token delegation, read default; release note
 -:  ------- > 11:  e2a32d5 wiki: delegation bound covers tokens and keys, not web sessions
 1:  2240cff = 12:  cab50f5 store: ssh_keys.expires_at; expired keys are not live
 2:  f10d090 = 13:  7f5c45d sshd: refuse expired keys at auth and per exec; expiring keys cannot mint
 3:  5fea0e6 = 14:  44e5fb3 keys: --ttl on keys add and repo deploy-key add; lists show last use and expiry
 4:  e54f028 ! 15:  1ed9fb9 wiki: key expiry
    @@ .gitbay/wiki/Architecture/09-Controls.org: chapter names of OWASP ASVS 4.0 where
     -| Credential expiry                           | partial  | API tokens optional; SSH and deploy keys none (#277)                    |
     +| Credential expiry                           | in place | optional =--ttl= on API tokens, SSH and deploy keys; checked at auth and per exec |
      | Revocation takes effect immediately         | in place | removing a key or disabling an account closes its connections; every exec re-reads its key (=internal/sshd/sshd.go=) |
    - | Delegation bounded by the delegating credential | in place | expiring tokens refused on =MintsCredential= commands; credentials record their creating token (=internal/control/control.go=) |
    + | Delegation bounded by the delegating credential | partial | expiring tokens refused on =MintsCredential= commands; credentials record their creating token (=internal/control/control.go=); a web session can still mint credentials that outlive it (#297) |
      
     
      ## .gitbay/wiki/Architecture/10-Known-Gaps.org ##
    @@ .gitbay/wiki/Users.org: A key's label is the comment on its =authorized_keys= li
     
      ## CHANGELOG.org ##
     @@ CHANGELOG.org: must add =--scope full=. Existing tokens keep their scope.
    -   those too.
    +   those too (#257).
      - Removing an SSH key, a deploy key, or disabling an account closes the
        connections the key opened, a push in flight included (#256).
     +- =keys add= and =repo deploy-key add= take =--ttl=; an expired key is
 5:  498c90d = 16:  03040d2 control: keys add refuses --ttl 0h and negative
 6:  3a83e2a = 17:  2ddf238 control: token list uses expiresText, not relAge, for expiry
 -:  ------- > 18:  32a5f76 control: key lists fit 60 columns; headers clip with their column
 -:  ------- > 19:  a8ba660 sshd: an expired key counts against the auth limiter
 -:  ------- > 20:  253e1a2 token: create refuses a zero or negative --ttl